Impact
Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross‑site scripting. An unauthenticated attacker could submit a payload through a public Express Form, and the malicious code subsequently executes in an administrator's dashboard session when that entry is viewed, or in any visitor's browser, allowing actions to be performed with the user's privileges.
Affected Systems
Concrete CMS installations that are running any version earlier than 9.5.3 are affected. The vulnerability was identified in the official release announcements for Concrete CMS 9.5.3, which contains the remediation. The product name is Concrete CMS.
Risk and Exploitability
The flaw has a CVSS v4.0 score of 2.3, indicating low impact severity. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the flaw by submitting a crafted payload through an Express form that is publicly accessible. Because the data is stored, the malicious code executes each time the associated entry is rendered, offering potential for session hijacking, defacement, or user‑agent phishing. The lack of credentials reduces the barrier to entry, but the actual damage depends on who views the content – an administrator or a passive visitor.
OpenCVE Enrichment